论文标题
隐私政策理解的挑战和影响
The Challenges and Impact of Privacy Policy Comprehension
论文作者
论文摘要
新的信息和通信技术提供商收集了越来越多的个人数据,其中很多是用户生成的。除非使用政策对隐私友好,否则这会使用户容易受到隐私风险的影响,例如通过公共数据可见性接触或通过二级数据使用对其数据进行侵入性商业化。由于复杂的隐私政策,许多在线服务的用户不愿同意隐私侵害实践。为了使用户更多地控制其隐私,学者和监管机构已推动简短,简单和突出的隐私政策。前提是用户将看到并理解此类政策,然后合理地调整其披露行为。在本文中,在社交网络服务网站的用例中,我们表明此前提不存在。我们邀请了214个常规Facebook用户加入一个新的虚拟社交网络。我们通过实验操纵了不可避免和简单的隐私政策的隐私友好性。我们一半的参与者甚至误解了这项透明的隐私政策。当存在二次数据使用的隐私威胁时,用户记得这些策略比实际上更友好,并且不知不觉地上传了更多数据。为了减轻这种行为陷阱,我们提出设计建议,以提高知情同意的质量。
The new information and communication technology providers collect increasing amounts of personal data, a lot of which is user generated. Unless use policies are privacy-friendly, this leaves users vulnerable to privacy risks such as exposure through public data visibility or intrusive commercialisation of their data through secondary data use. Due to complex privacy policies, many users of online services unwillingly agree to privacy-intruding practices. To give users more control over their privacy, scholars and regulators have pushed for short, simple, and prominent privacy policies. The premise has been that users will see and comprehend such policies, and then rationally adjust their disclosure behaviour. In this paper, on a use case of social network service site, we show that this premise does not hold. We invited 214 regular Facebook users to join a new fictitious social network. We experimentally manipulated the privacy-friendliness of an unavoidable and simple privacy policy. Half of our participants miscomprehended even this transparent privacy policy. When privacy threats of secondary data use were present, users remembered the policies as more privacy-friendly than they actually were and unwittingly uploaded more data. To mitigate such behavioural pitfalls we present design recommendations to improve the quality of informed consent.